Junglewise Threat Intelligence

CVE-2026-76945: Ebyte NE2-D11 authentication bypass via client-side token manipulation

CVE-2026-76945 · Severity: high · CVSS 7.5 · Published 2026-08-28

Executive brief

The Ebyte NE2-D11 is an industrial gateway device used in critical manufacturing and energy sectors to manage network communications. Due to insufficient server-side validation of authentication tokens, attackers can replay or manipulate these tokens to gain unauthorized administrative access to the device, potentially allowing them to modify critical configuration, disrupt operations, or steal sensitive data.

Technical details

The vulnerability stems from client-managed authentication tokens without sufficient server-side validation (CWE-306, CWE-521). The device relies on client-side authentication logic that can be reproduced by unauthenticated users, allowing attackers to generate valid authentication requests and bypass authentication. The affected component is the web management interface of Ebyte NE2-D11 firmware FW-9167-0-11. An attacker with network access can exploit this vulnerability without authentication or user interaction to obtain administrative access. Additional flaws include cleartext transmission of sensitive information and plaintext exposure of credentials in the management interface. Vendor has acknowledged the vulnerabilities but has not released patches as of the advisory publication date.

Affected products

  • Ebyte NE2-D11 FW-9167-0-11

Timeline

  • 2026-08-25: disclosed

References

Related threats